Sysdig
Coverage of Sysdig in the Nexus archive.
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Sysdig researchers linked a new ransomware attack using ENCFORGE to JADEPUFFER, an AI-agent-driven operator. ENCFORGE targets AI infrastructure files like model weights and training datasets on Langflow servers.
- Cybersecurity firm says it found 'the first documented case' of AI agentic ransomware
Sysdig researchers documented the first agentic AI ransomware attack, named 'Jade Puffer,' where an AI model orchestrated a complex ransomware campaign. The attack lowered the barrier to entry for ransomware by automating tasks like credential harvesting and generating ransom notes, with minimal cost to attackers.
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Sysdig, a security firm, reports discovering the first ransomware attack fully executed by an AI agent named JADEPUFFER. The AI agent conducted a database ransomware attack by infiltrating systems, stealing credentials, moving laterally in the network, and encrypting/wiping a company's production database.
- Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
A critical remote code execution vulnerability (CVE-2026-39987) in Marimo, a Python data science notebook, was exploited within 10 hours of disclosure. The flaw affects all versions up to a specific release and was identified by Sysdig with a CVSS score of 9.3.